Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE
Overview
Vercel has issued security patches for two serious vulnerabilities in the Next.js framework that could allow attackers to execute code remotely without authentication. The first vulnerability arises from the handling of AVIF image files, which can be manipulated to exploit the system. The second flaw is a path traversal issue that affects installations on Windows filesystems, enabling unauthorized access to files. These vulnerabilities are particularly concerning because they can be exploited without any user interaction, putting many applications at risk if they use Next.js. Developers using this framework should prioritize updating to the latest version to mitigate these risks.
Key Takeaways
- Affected Systems: Next.js framework, specifically installations using AVIF image files and Windows filesystems.
- Action Required: Vercel recommends updating to the latest version of Next.
- Timeline: Newly disclosed
Original Article Summary
Credit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF image files and the other through a path traversal flaw affecting servers that use a Windows filesystem. The Windows path traversal, tracked as CVE-2026-75604&
Impact
Next.js framework, specifically installations using AVIF image files and Windows filesystems.
Exploitation Status
The exploitation status is currently unknown. Monitor vendor advisories and security bulletins for updates.
Timeline
Newly disclosed
Remediation
Vercel recommends updating to the latest version of Next.js to apply the security patches addressing these vulnerabilities. Specific version numbers were not provided, but developers should ensure they are using the most current release.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Windows, CVE, Microsoft, and 4 more.